MAL-2026-10897
Malicious code in golan125-homepage-test (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (705b0dc2e3b9aafb6d0e72ecb5ad51d873cd59104a045f74bb27161c87a24960) Package self-identifies as a security research test ('Security research test - do not install'). The package.json `homepage` field contains `javascript:alert(document.domain)`, which is an XSS probe targeting any registry or UI frontend that renders homepage values as clickable links without sanitization. The package has no lifecycle scripts (no preinstall/install/postinstall), no network I/O, and `index.js` exports an empty object — installing or requiring this package does not harm the installer's machine. The XSS probe targets registry web UI rendering, not developers who install the package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for golan125-homepage-test (npm). Pin to a known-safe version or switch to an alternative.